Getting Data In

[monitor:///opt/atlassian/.../*.log] does not pick up logs in /opt/atlassian/fisheye-data/var/log

di2esysadmin
Path Finder

An inputs.conf entry:

[monitor:///opt/atlassian/.../*.log]

sourcetype=atlassian

crcSalt = SOURCE (pretend there are brackets around SOURCE)

It's processing files in /opt/atlassian/fisheye-data/var/cache (I know this because there are messages in the splunk log re files in the cache dir.) but appears to be completely skipping files in the log directory. /opt/atlassian/fisheye-data/var/log

Help! 🙂

Thanks.

Tags (2)
0 Karma

di2esysadmin
Path Finder

Disregard. It's working now. Apparently I'm lacking in patience.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...